Applied Oversight

Insights · State AI law

Colorado regulated chatbots. Yours is probably exempt — here's how to check.

On July 1, 2026, Governor Polis signed House Bill 26-1263, making Colorado the first state with a standalone law governing consumer-facing conversational AI. The headlines say Colorado just regulated chatbots. If your company runs a customer-service bot, your first question is the right one: does this reach us?

For most businesses, the honest answer is probably not. But the statute requires you to confirm that, and the confirmation has conditions.

Who this touches

The law covers "conversational artificial intelligence services": AI systems accessible to the general public that primarily simulate human conversation through adaptive text, visuals, or audio. Think open-ended companion apps and character-style AI: the systems the legislature was worried about when it wrote duties around emotional dependence and teen safety.

Then comes the part the headlines skip. The definition carries twelve express exclusions (C.R.S. § 6-1-1701(3.5)(b)), and they carve out most of what businesses actually run: bots primarily designed for customer service, commerce, and transactions (product recommendations, ordering, payments, returns); narrow-topic bots; tools built for business productivity and internal use; video-game and theme-park characters; HIPAA-covered healthcare tools; educational tools; and embedded features that aren't designed for emotional companionship.

So a support widget that resets passwords and tracks orders is out of scope. A companion app that chats about anything, remembers your day, and simulates a friendship is squarely in it.

What the law actually requires, if you're covered

Operators of covered services owe, on and after January 1, 2027 (C.R.S. § 6-1-1708):

  • AI-not-human disclosure at the start of each day's first interaction, at least every three hours of continuous conversation (or persistently on screen), and whenever a user asks.
  • Age estimation using commercially reasonable methods, and for known minors a safeguard package: no engagement-bait reward mechanics, technical measures against sexually explicit content, measures against simulated emotional dependence (including claims of being human or romantic-companionship behavior), and privacy tools for minors and their parents.
  • A suicide and self-harm response protocol that refers users to crisis services (expressly not to law enforcement), with escalation procedures.
  • No representing chatbot output as provided by, endorsed by, or equivalent to licensed health-care, legal, or mental-health professionals, or dietitians.
  • An annual report to the Colorado Attorney General starting July 1, 2027, covering crisis-referral counts and safeguard efficacy.

What to do about it

  1. Screen every chatbot you operate, and write the determination down. The exclusions are real, but they're a legal conclusion, and you have to be able to show your work. A one-page record ("this bot is excluded under § 6-1-1701(3.5)(b)(II) because it is primarily designed for customer service") is cheap insurance and exactly what you'd want in hand if the AG ever asks.
  2. Read the conditions inside the exclusions. This is the trap. The narrow-topic and voice-assistant exclusions only apply if the bot cannot generate sexually explicit content or maintain dialogue about self-harm. An open-ended LLM bolted onto a support flow without guardrails may not qualify cleanly for the exemption its use case suggests. Your bot's technical capabilities matter, not just its job description.
  3. Check the "operator" definition against your vendor arrangements. An operator includes anyone who offers a covered service to a consumer, including one a vendor built (C.R.S. § 6-1-1701(15.5)). White-labeling a vendor's companion-style AI can make you the operator.
  4. Audit your bot's marketing and outputs for professional-services claims. Marketing language that compares a bot to a therapist, lawyer, or dietitian is now a Colorado compliance problem, whether or not the rest of the law reaches you. Overstated AI claims were already an FTC problem everywhere.
  5. If you're covered, start the build now. Age estimation, disclosure cadence, and crisis protocols are engineering work with a January 1, 2027 deadline, and the annual AG report six months later means you need counting infrastructure from day one.

The honest caveat

The Attorney General has discretionary rulemaking over this act and is running a combined rulemaking with Colorado's new ADMT law; the content of the annual report, in particular, is expressly left to the AG to define. Draft regulations are expected at the end of summer 2026. The edges of "offering" a service (especially for embedded vendor bots) haven't been tested. If your bot sits anywhere near the companion end of the spectrum, treat today's analysis as a starting position, not a final answer.

This article is educational commentary and is not legal advice. Every legal claim traces to the enrolled text of HB 26-1263.

Ten minutes of questions.
A one-page map of your AI obligations.

Get your free exposure scan